Category | Started | Completed | Duration | Log |
---|---|---|---|---|
FILE | 2023-11-15 11:41:05 | 2023-11-15 11:41:05 | 0 seconds | Show Log |
File Name | hdwwiz.exe |
---|---|
File Size | 77824 bytes |
File Type | PE32+ executable (GUI) x86-64, for MS Windows |
MD5 | 7de017df8d0ecfd5e4d901d53bd50f81 |
SHA1 | 6b297f20f5fe8ac9730e6581139b83ec9ce048cd |
SHA256 | 79ce21b1dc200d81018d1421b11944e6ac454cd54c541b222f1ed1cd08d0fc86 |
SHA512 | bd151ed61c50239beb7ae4445ee076dcab2303564bf2cd2acaf064d9fa4edac4765c9a2212665e6a87b31d1a3cb2a4716faf3b2826469c4cd4a0f6da9c840241 |
CRC32 | E639A6FC |
Ssdeep | 384:D5l8toF7JMWW2nw0W6yWT4650Ingu+n6aJTIXFJhjhxhWM1hvYvfeHviODnMObvt:D5+o3bws/4G0In3BhzhWM1GOVz17 |
ClamAV | None matched |
Yara | None matched |
No hosts contacted.
No domains contacted.
Image Base | 0x140000000 |
---|---|
Entry Point | 0x140001150 |
Reported Checksum | 0x0001b39e |
Actual Checksum | 0x0001b39e |
Minimum OS Version | 10.0 |
PDB Path | HdwWiz.pdb |
Compile Time | 1971-11-10 04:30:12 |
Icon | |
Icon Exact Hash | a7698db66488a2ab35c8302bbe546fe8 |
Icon Similarity Hash | 28d9d08a641261d537d3588bdff99552 |
LegalCopyright | \xa9 Microsoft Corporation. All rights reserved. |
---|---|
InternalName | HdwWiz.EXE |
FileVersion | 10.0.22621.1 (WinBuild.160101.0800) |
CompanyName | Microsoft Corporation |
ProductName | Microsoft\xae Windows\xae Operating System |
ProductVersion | 10.0.22621.1 |
FileDescription | Add Hardware Wizard |
OriginalFilename | HdwWiz.EXE |
Translation | 0x0409 0x04b0 |
Name | Virtual Address | Virtual Size | Size of Raw Data | Characteristics | Entropy |
---|---|---|---|---|---|
.text | 0x00001000 | 0x00000a40 | 0x00001000 | IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ | 4.33 |
.rdata | 0x00002000 | 0x00000bae | 0x00001000 | IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ | 3.22 |
.data | 0x00003000 | 0x00000680 | 0x00001000 | IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE | 0.05 |
.pdata | 0x00004000 | 0x000000d8 | 0x00001000 | IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ | 0.31 |
.rsrc | 0x00005000 | 0x0000cc58 | 0x0000d000 | IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ | 5.02 |
.reloc | 0x00012000 | 0x00000030 | 0x00001000 | IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ | 0.11 |
Name | Offset | Size | Language | Sub-language | Entropy | File type |
---|---|---|---|---|---|---|
MUI | 0x00011b88 | 0x000000d0 | LANG_ENGLISH | SUBLANG_ENGLISH_US | 2.70 | data |
RT_ICON | 0x000116a8 | 0x00000468 | LANG_ENGLISH | SUBLANG_ENGLISH_US | 3.56 | GLS_BINARY_LSB_FIRST |
RT_ICON | 0x000116a8 | 0x00000468 | LANG_ENGLISH | SUBLANG_ENGLISH_US | 3.56 | GLS_BINARY_LSB_FIRST |
RT_ICON | 0x000116a8 | 0x00000468 | LANG_ENGLISH | SUBLANG_ENGLISH_US | 3.56 | GLS_BINARY_LSB_FIRST |
RT_ICON | 0x000116a8 | 0x00000468 | LANG_ENGLISH | SUBLANG_ENGLISH_US | 3.56 | GLS_BINARY_LSB_FIRST |
RT_ICON | 0x000116a8 | 0x00000468 | LANG_ENGLISH | SUBLANG_ENGLISH_US | 3.56 | GLS_BINARY_LSB_FIRST |
RT_ICON | 0x000116a8 | 0x00000468 | LANG_ENGLISH | SUBLANG_ENGLISH_US | 3.56 | GLS_BINARY_LSB_FIRST |
RT_ICON | 0x000116a8 | 0x00000468 | LANG_ENGLISH | SUBLANG_ENGLISH_US | 3.56 | GLS_BINARY_LSB_FIRST |
RT_ICON | 0x000116a8 | 0x00000468 | LANG_ENGLISH | SUBLANG_ENGLISH_US | 3.56 | GLS_BINARY_LSB_FIRST |
RT_GROUP_ICON | 0x00011b10 | 0x00000076 | LANG_ENGLISH | SUBLANG_ENGLISH_US | 2.94 | MS Windows icon resource - 8 icons, 256-colors |
RT_VERSION | 0x000055d8 | 0x00000394 | LANG_ENGLISH | SUBLANG_ENGLISH_US | 3.48 | data |
RT_MANIFEST | 0x000052d0 | 0x00000305 | LANG_ENGLISH | SUBLANG_ENGLISH_US | 4.95 | XML document text |
No hosts contacted.
No TCP connections recorded.
No UDP connections recorded.
No domains contacted.
No HTTP requests performed.
No SMTP traffic performed.
No IRC requests performed.
No ICMP traffic performed.
No CIF Results
No Suricata Alerts
No Suricata TLS
No Suricata HTTP
JSON Report | Download |
---|
Task ID | 2438 |
---|---|
Mongo ID | 655502b62694ed5bda0b5ea2 |
Cuckoo release | 1.3-NG |